Back to the blog

Jamf Security Cloud: migrate platform-scoped filters before October 30, 2026

Article created September 13, 2026 · Source reviewed September 13, 2026 · Official source: Jamf · Topic: network security, content filtering and Apple fleet management

Jamf has deprecated platform scoping for content-filtering rules in Jamf Security Cloud. Existing rules remain in place, but the selector is scheduled for removal on October 30, 2026. To retain different behavior across Mac, iPhone and iPad, organizations must now use platform-specific device groups.

1. What Jamf is actually announcing

The official documentation states that selecting a platform within a content-filtering rule has been deprecated since August 31, 2026. Existing rules continue to operate until the announced removal of the selector on October 30, 2026. Jamf instructs administrators to move devices into platform-specific groups and then configure each group’s filtering policy.

Content filtering itself is not being removed. The change moves where targeting is expressed: platform differences must no longer sit as a condition inside the rule, but in device-group membership and the associated policy.

2. Why a mechanical conversion is risky

A rule may currently combine web categories, business exceptions, populations and platforms. Copying it across several groups without first producing an inventory can create scope gaps, duplicates or a different evaluation order. An application allowed on Mac but blocked on iPhone could become unavailable, or an exception intended for a restricted population could inadvertently expand.

For every rule, teams should document its purpose, platforms, target groups, exceptions, owner and test evidence. MDM and Apple Business Manager remain essential for attaching and classifying devices, but consistency between inventory, groups and Jamf Security Cloud policies becomes the real control point.

3. What does this change for a Belgian or French enterprise?

For an SMB, the priority is to avoid discovering after the deadline that one shared policy no longer reflects differences between Mac and mobile devices. For a mid-market company, large enterprise or public body in Belgium or France, the migration must also account for subsidiaries, BYOD, shared devices and local security owners.

Security teams need to demonstrate that the intended filtering still applies to the correct population. This traceability matters especially where rules support internal policy, usage segmentation or a compliance requirement.

4. Underside’s view: make groups governed data

Our view is that this change turns device-group quality into a direct dependency of network security. A group populated late, defined by an ambiguous membership rule or lacking an owner can leave a correctly enrolled device under the wrong filtering policy.

The migration should therefore connect the inventory source, group criteria, Jamf Security Cloud policy and an observable network test. It complements the governance of Jamf integrations and declarative Apple web-content filtering, without confusing native MDM controls with cloud security policy.

5. Recommended migration plan

Objective: preserve differentiated, verifiable filtering across Mac, iPhone and iPad before the platform selector is removed.

Audit your Jamf Security Cloud policies

Official source: Jamf Security Cloud Release Notes — Deprecations and Removals, reviewed September 13, 2026.